An elemental block can include an XSS payload, which can be executed when viewing the "Content blocks in use" report.
The vulnerability is specific to that report and is a result of failure to cast input prior to including it in the grid field.
{ "github_reviewed_at": "2025-04-10T13:38:53Z", "cwe_ids": [ "CWE-79" ], "nvd_published_at": "2025-04-10T13:15:51Z", "severity": "MODERATE", "github_reviewed": true }